Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
volatility — 高度なメモリフォレンジックフレームワーク | Kitploit
ツール/GitHubGitHub/volatilityfoundation/volatility
メモリフォレンジック脆弱性分析リバースエンジニアリングフォレンジックマルウェア分析デジタルフォレンジックインシデントレスポンスArchived
GitHubvolatilityfoundation/volatility

volatility

高度なメモリフォレンジックフレームワーク

リポジトリを見る
8.1k1.3k591年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
ウェブサイト

This project is archived. See Volatility 3 for modern investigations: https://github.com/volatilityfoundation/volatility3

============================================================================ Volatility Framework - 揮発性メモリ抽出ユーティリティフレームワーク

Volatility Framework は、GNU General Public License のもとで Python で実装された、完全にオープンなツール群です。揮発性メモリ(RAM)サンプルからデジタルアーティファクトを抽出するために使用されます。抽出手法は調査対象のシステムから完全に独立して実行され、システムの実行時状態を可視化します。このフレームワークは、揮発性メモリサンプルからデジタルアーティファクトを抽出する際の技術と複雑性を紹介し、この刺激的な研究分野におけるさらなる作業のためのプラットフォームを提供することを目的としています。

Volatility の配布物は以下から入手可能です: http://www.volatilityfoundation.org/#!releases/component_71401

Volatility は Python (http://www.python.org) をサポートする任意のプラットフォームで動作します。

Volatility は以下のメモリイメージの調査をサポートしています:

Windows:

  • 32-bit Windows XP Service Pack 2 and 3
  • 32-bit Windows 2003 Server Service Pack 0, 1, 2
  • 32-bit Windows Vista Service Pack 0, 1, 2
  • 32-bit Windows 2008 Server Service Pack 1, 2 (there is no SP0)
  • 32-bit Windows 7 Service Pack 0, 1
  • 32-bit Windows 8, 8.1, and 8.1 Update 1
  • 32-bit Windows 10 (initial support)
  • 64-bit Windows XP Service Pack 1 and 2 (there is no SP0)
  • 64-bit Windows 2003 Server Service Pack 1 and 2 (there is no SP0)
  • 64-bit Windows Vista Service Pack 0, 1, 2
  • 64-bit Windows 2008 Server Service Pack 1 and 2 (there is no SP0)
  • 64-bit Windows 2008 R2 Server Service Pack 0 and 1
  • 64-bit Windows 7 Service Pack 0 and 1
  • 64-bit Windows 8, 8.1, and 8.1 Update 1
  • 64-bit Windows Server 2012 and 2012 R2
  • 64-bit Windows 10 (including at least 10.0.19041)
  • 64-bit Windows Server 2016 (including at least 10.0.19041)

注:最近パッチが適用された Windows 7(以降)のメモリサンプルとの互換性に関する注意事項については、以下のリンクのガイドラインを参照してください:

https://github.com/volatilityfoundation/volatility/wiki/2.6-Win-Profiles

Linux:

  • 32-bit Linux kernels 2.6.11 to 5.5
  • 64-bit Linux kernels 2.6.11 to 5.5
  • OpenSuSE, Ubuntu, Debian, CentOS, Fedora, Mandriva, etc

Mac OSX:

  • 32-bit 10.5.x Leopard (the only 64-bit 10.5 is Server, which isn't supported)
  • 32-bit 10.6.x Snow Leopard
  • 64-bit 10.6.x Snow Leopard
  • 32-bit 10.7.x Lion
  • 64-bit 10.7.x Lion
  • 64-bit 10.8.x Mountain Lion (there is no 32-bit version)
  • 64-bit 10.9.x Mavericks (there is no 32-bit version)
  • 64-bit 10.10.x Yosemite (there is no 32-bit version)
  • 64-bit 10.11.x El Capitan (there is no 32-bit version)
  • 64-bit 10.12.x Sierra (there is no 32-bit version)
  • 64-bit 10.13.x High Sierra (there is no 32-bit version))
  • 64-bit 10.14.x Mojave (there is no 32-bit version)
  • 64-bit 10.15.x Catalina (there is no 32-bit version)

Volatility はメモリサンプルの取得機能を提供しません。取得には、無料および商用のソリューションが利用可能です。適切な取得ソリューションについての提案が必要な場合は、以下のアドレスまでお問い合わせください:

volatility (at) volatilityfoundation (dot) org

Volatility はさまざまなサンプルファイル形式をサポートし、これらの形式間で変換する機能を提供します:

  • Raw linear sample (dd)
  • Hibernation file (from Windows 7 and earlier)
  • Crash dump file
  • VirtualBox ELF64 core dump
  • VMware saved state and snapshot files
  • EWF format (E01)
  • LiME format
  • Mach-O file format
  • QEMU virtual machine dumps
  • Firewire
  • HPAK (FDPro)

機能のより詳細なリストについては、以下を参照してください:

https://github.com/volatilityfoundation/volatility/wiki

また、コミュニティプラグインリポジトリも参照してください:

https://github.com/volatilityfoundation/community

Example Data

Volatility を試してみたい場合は、以下の URL からメモリイメージのサンプルをダウンロードできます:

https://github.com/volatilityfoundation/volatility/wiki/Memory-Samples

Mailing Lists

Volatility のユーザーと開発者をサポートするメーリングリストは、以下のアドレスにあります:

http://lists.volatilesystems.com/mailman/listinfo

Contact

情報やリクエストについては、以下までお問い合わせください:

Volatility Foundation

Web: http://www.volatilityfoundation.org http://volatility-labs.blogspot.com http://volatility.tumblr.com

Email: volatility (at) volatilityfoundation (dot) org

IRC: #volatility on freenode

Twitter: @volatility

Requirements

  • Python 2.6 or later, but not 3.0. http://www.python.org

一部のプラグインには他の要件があります。詳細は以下を参照してください: https://github.com/volatilityfoundation/volatility/wiki/Installation

Quick Start

  1. Unpack the latest version of Volatility from volatilityfoundation.org

  2. To see available options, run "python vol.py -h" or "python vol.py --info"

    Example:

$ python vol.py --info Volatility Foundation Volatility Framework 2.6

Address Spaces

AMD64PagedMemory - Standard AMD 64-bit address space. ArmAddressSpace - Address space for ARM processors FileAddressSpace - This is a direct file AS. HPAKAddressSpace - This AS supports the HPAK format IA32PagedMemory - Standard IA-32 paging address space. IA32PagedMemoryPae - This class implements the IA-32 PAE paging address space. It is responsible LimeAddressSpace - Address space for Lime LinuxAMD64PagedMemory - Linux-specific AMD 64-bit address space. MachOAddressSpace - Address space for mach-o files to support atc-ny memory reader OSXPmemELF - This AS supports VirtualBox ELF64 coredump format QemuCoreDumpElf - This AS supports Qemu ELF32 and ELF64 coredump format VMWareAddressSpace - This AS supports VMware snapshot (VMSS) and saved state (VMSS) files VMWareMetaAddressSpace - This AS supports the VMEM format with VMSN/VMSS metadata VirtualBoxCoreDumpElf64 - This AS supports VirtualBox ELF64 coredump format Win10AMD64PagedMemory - Windows 10-specific AMD 64-bit address space. WindowsAMD64PagedMemory - Windows-specific AMD 64-bit address space. WindowsCrashDumpSpace32 - This AS supports windows Crash Dump format WindowsCrashDumpSpace64 - This AS supports windows Crash Dump format WindowsCrashDumpSpace64BitMap - This AS supports Windows BitMap Crash Dump format WindowsHiberFileSpace32 - This is a hibernate address space for windows hibernation files.

ツールをダウンロード